CVE-2025-2334

MEDIUM

springboot-openai-chatgpt e84f6f5 - Improper Access Control in Chat History Handler

Title source: llm
STIX 2.1

Description

A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat History Handler. The manipulation of the argument chatListId leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit
https://www.cnblogs.com/aibot/p/18732182
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.299799
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.299799
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.505688

Scores

CVSS v3 5.4
EPSS 0.0050
EPSS Percentile 38.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-284
Status published
Products (1)
274056675/springboot-openai-chatgpt 2024-12-29
Published Mar 15, 2025
Tracked Since Feb 18, 2026